SECURITY · POSTURE
Compatible with sponsor banks, regulators, and developers.
In that order of restraint. Architectural choices that map to the standards a SARB examiner or a sponsor-bank risk team would expect — named, dated, and externally auditable.
ARCHITECTURE
Sponsor-bank model, not a bank
Orchura is an FSP under FAIS, sitting on a sponsor-bank rail. We are not a bank, not a card scheme, and not a crypto exchange — and the codebase reflects that boundary.
FAISSARB · NPS
VAULT
PCI DSS Level 1 architecture
Card data is tokenized at the edge. No PAN persisted in our systems. The vault is held by an HSM-backed sub-processor; merchants reference tokens, never raw numbers.
PCI DSS L1HSM · TLS 1.3 mTLS
LEDGER
Audit-safe double-entry ledger
Every primitive — collections, payables, retries, reversals — writes append-only to a double-entry ledger that survives audit. Time-bounded WORM retention per regulator class.
ISO 27001 controlsWORM · append-only
DATA
POPIA-grade data handling
Personal data is processed under explicit lawful basis. Data subject rights are wired into the API — access, deletion, portability return through the same primitive. Information Officer registered with the Regulator.
POPIAGDPR · adequacy